What happened
The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Affected versions
WP Fastest Cache: before 1.2.2 (semver) Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
wpscan.comNVD reference2023-12-04Verifiedwpscan.comNVD reference2023-12-04VerifiedSploitusUnauthenticated time-based blind SQL injection in WP Fastest Cache ≤ 1.2.2 via logged-in cookie.zhairiazzeddine2026-09-09T20:19:59Verifiedzhairiazzeddine/Exploit-CVE-2023-6063-PoC-VulnUnauthenticated time-based blind SQL injection in WP Fastest Cache ≤ 1.2.2 via logged-in cookie.zhairiazzeddine2026-09-09T20:19:59VerifiedSource timeline
Discovered through SploitusView source ↗
CVE record published by NVDView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.